#searchleak
For the "we haven't seen enterprise agents leaking info lately because it's now a solved problem*" crowd

(*heard this as recently as friday)

www.varonis.com/blog/searchl...
SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon
Varonis Threat Labs discovered SearchLeak, a critical vulnerability chain in Microsoft 365 Copilot Enterprise that allows an attacker to steal sensitive data — MFA codes, email messages, meeting detai...
www.varonis.com
June 15, 2026 at 3:25 PM
KI und Copilot ist sau cool - ein Suchstring in einer URL reicht, um von einem Opfer E-Mails, Adressen, SharePoint-Dokumente, OneDrive-Inhalte etc. aus einer Unternehmensumgebung zu exfiltrieren. #SearchLeak macht es möglich.

borncity.com/blog/2026/06...
SearchLeak: Neuer, kritischer Ein-Klick-Exploit für Microsoft Copilot
Ein Klick auf einen vertrauenswürdigen Link reicht, um ein System über Microsoft Copilot vollständig zu kompromittieren. Keine gefälschte Anmeldeseite samt Phishing-Angriff, und kein Passwort-Klau.
borncity.com
June 15, 2026 at 10:58 PM
Read this insight from Patrick Spencer of Kiteworks from June 23, 2026. "Microsoft 365 Copilot SearchLeak (CVE-2026-42824): When Your #AI Assistant Becomes an Exfiltration Tool" 🫨 cybersec.kiteworks.com/s/microsoft-...
July 20, 2026 at 1:31 PM
New attack turned Microsoft 365 Copilot into 1-click data theft tool
New attack turned Microsoft 365 Copilot into 1-click data theft tool
A critical vulnerability chain dubbed SearchLeak in Microsoft 365 Copilot Enterprise could allow attackers to steal sensitive data from a target's mailbox, OneDrive, or SharePoint account through a specially crafted URL.
www.bleepingcomputer.com
June 15, 2026 at 1:44 PM
Critical Copilot vulnerability allowed hackers to steal 2FA code from users
Critical Copilot vulnerability allowed hackers to steal 2FA code from users
SearchLeak exploit shows why the industry's approach to LLM security fails over and over.
arstechnica.com
June 16, 2026 at 10:11 PM
How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon
SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon
Varonis Threat Labs discovered SearchLeak, a critical vulnerability chain in Microsoft 365 Copilot Enterprise that allows an attacker to steal sensitive data — MFA codes, email messages, meeting detai...
www.varonis.com
June 15, 2026 at 6:46 PM
A critical vulnerability chain dubbed SearchLeak in Microsoft 365 Copilot Enterprise could allow attackers to steal sensitive data from a target's mailbox, OneDrive, or SharePoint account through a specially crafted URL.
New attack turned Microsoft 365 Copilot into 1-click data theft tool
A critical vulnerability chain dubbed SearchLeak in Microsoft 365 Copilot Enterprise could allow attackers to steal sensitive data from a target's mailbox, OneDrive, or SharePoint account through a specially crafted URL.
www.bleepingcomputer.com
June 15, 2026 at 1:00 PM
Indirect prompt injection attacks are really in their infancy. As we enable more agents and more tools/integrations, the possibilities for this *fundamentally unfixable* vulnerability get scarier.
New attack turned Microsoft 365 Copilot into 1-click data theft tool
A critical vulnerability chain dubbed SearchLeak in Microsoft 365 Copilot Enterprise could allow attackers to steal sensitive data from a target's mailbox, OneDrive, or SharePoint account through a specially crafted URL.
www.bleepingcomputer.com
June 15, 2026 at 1:48 PM
For a year, 'prompt injection could exfiltrate your data' was a warning. Varonis made it a CVE. SearchLeak chained a prompt injection into Microsoft 365 Copilot with two web bugs: one click on a real microsoft.com link silently stole MFA codes, email, and files. Now patched.
A one-click Copilot flaw, SearchLeak, could steal MFA codes, email, and files
Varonis disclosed SearchLeak (CVE-2026-42824), a max-severity Microsoft 365 Copilot flaw chaining a prompt injection with two web bugs so one click on a real microsoft.com link silently exfiltrated MFA codes, email, and files. Patched server-side.
zubnet.ai
June 17, 2026 at 12:09 AM
Best part of this 'AI revolution' is the amazingly broad attack surface it has opened for enterprising human intelligence.

Get recked, Microslop~

arstechnica.com/security/202...
Critical Copilot vulnerability allowed hackers to seal 2FA code from users
SearchLeak exploit shows why the industry's approach to LLM security fails over and over.
arstechnica.com
June 16, 2026 at 12:20 PM
📰 Senjata Makan Tuan: Celah "SearchLeak" Ubah Microsoft 365 Copilot Menjadi Alat Pencuri Data Instan

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/06/15/celah-searchleak-copilot-microsoft-365-bocor/

#ai
#c#aid#cloudl#copilot2#cve42824 #hacke#hackera#keamananSibero#microsofto#microsoft
June 15, 2026 at 2:29 PM
KI-Tools in Unternehmen, die als Erweiterung der Benutzersitzung agieren, sind ein erhebliches Sicherheitsrisiko. Die Schwachstelle SearchLeak verdeutlicht den Handlungsbedarf....
👉 [lesen]
July 20, 2026 at 10:37 AM
KI-Tools in Unternehmen, die als Erweiterung der Benutzersitzung agieren, sind ein erhebliches Sicherheitsrisiko. Die Schwachstelle SearchLeak verdeutlicht den Handlungsbedarf....
👉 [lesen]
July 19, 2026 at 9:40 AM
New blog post: M365 Copilot: The AI That Spills the Beans, Literally

The "SearchLeak" vulnerability in M365 Copilot shows exactly what happens...

https://rhodzy.com/blog/m365-copilot-the-ai-that-spills-the-beans-literally

#m365 #copilot #ai #security #dataleak #microsoft #enterpriseai #searchleak
M365 Copilot: The AI That Spills the Beans, Literally
The "SearchLeak" vulnerability in M365 Copilot shows exactly what happens when everyone rushes into AI without thinking about the massive security implications. One click, and your data's out the door.
rhodzy.com
June 23, 2026 at 6:00 AM
The Copilot #SearchLeak #Vulnerability chain shows how any #AI assistant can evolve from a productivity feature into a new path into data that inherits the user's reach. Kate O'Flaherty discusses the vulnerability chain: https://ow.ly/h6nm50ZoewJ
July 16, 2026 at 12:01 PM
The @varonis Threat Labs teams demonstrated that enterprise #AI assistants can be turned into a precision data exfiltration tool via a crafted link. #CVE-2026-42824 AKA #SearchLeak is a huge vulnerability chain in Microsoft 365 Copilot. HT HT @Kiteworks. cybersec.kiteworks.com/s/microsoft-...
Microsoft 365 Copilot SearchLeak (CVE-2026-42824): When Your AI Assistant Becomes an Exfiltration Tool
CVE-2026-42824 turns Microsoft 365 Copilot into a data exfiltration tool. Learn how the SearchLeak attack chain works and what defenders must do now.
cybersec.kiteworks.com
June 30, 2026 at 4:11 PM
A post on Reddit discusses how M365 Copilot was manipulated into becoming a tool for easy data theft. Dubbed "SearchLeak," this exploit allows users to exfiltrate sensitive information with just one click, raising concerns about the security of AI systems.
SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon
View post on Reddit.
reddit.com
June 15, 2026 at 5:42 PM
⚠️ Copilot leak used Bing as exfiltration proxy

SearchLeak abused Copilot’s q parameter and Bing image fetches to leak emails, files and MFA codes through trusted Microsoft infrastructure.

🔗 read more: thehackernews.com/2026/06/one-...

#ransomNews #cybersecurity
June 15, 2026 at 4:21 PM
New attack turned Microsoft 365 Copilot into 1-click data theft tool

A critical vulnerability chain dubbed SearchLeak in Microsoft 365 Copilot Enterprise could allow attackers to steal sensitive data from a target's mailbox, OneDrive, or SharePoint account through a…
#copilot #hackernews #microsoft
New attack turned Microsoft 365 Copilot into 1-click data theft tool
A critical vulnerability chain dubbed SearchLeak in Microsoft 365 Copilot Enterprise could allow attackers to steal sensitive data from a target's mailbox, OneDrive, or SharePoint account through a specially crafted URL. [...]
www.bleepingcomputer.com
June 16, 2026 at 4:20 AM
-New malware: Rokarolla, GlassWASM, Backdoor.Turn, Scales, Potemkin loader
-New UNC6508 group targets REDCap servers
-New Cisco SD-WAN zero-day
-New LiteSpeed zero-day
-CVE program on pace for record year
-New SearchLeak vulnerability
-Hacker hijacks half of Monero's P2Pool
June 17, 2026 at 7:32 AM
Microsoft 365 Copilot's 'SearchLeak' flaw allows one-click data theft. Apply updates now. #Microsoft365 #Copilot #SearchLeak #CyberSecurity #DataBreach #AI #SecurityUpdate thedailytechfeed.com/critical-mic...
June 15, 2026 at 3:32 PM
June 15, 2026 at 3:17 PM